Correct way to escape input data before passing to ODBC

前端 未结 1 1973
一生所求
一生所求 2020-12-17 23:55

I am very used to using MySQL and mysql_real_escape_string(), but I have been given a new PHP project that uses ODBC.

What is the correct way to escape user input in

相关标签:
1条回答
  • 2020-12-18 00:34

    Instead of string escaping the PHP ODBC driver uses prepared statements. Use odbc_prepare to prepare an SQL statement and odbc_execute to pass in the parameters and execute the statements. (This is similar to what you can do with PDO).

    0 讨论(0)
提交回复
热议问题